
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-92355 is a path traversal vulnerability in Octopus Server that allows an authenticated user with permission to modify non built-in external feeds to overwrite arbitrary files on the server, potentially leading to remote code execution in certain configurations. It was published on September 16, 2026, and affects Octopus Server versions from 2024.1.4131 up to (but not including) 2026.1.11725, versions 2026.2.0 up to 2026.2.13344, and versions 2026.3.0 up to 2026.3.11816. The vulnerability carries a CVSS v4.0 base score of 8.7 (High) (GitHub Advisory, Octopus Advisory).
The vulnerability is classified as CWE-22 (Improper Limitation of a Pathname to a Restricted Directory — 'Path Traversal'). When a user with permission to modify non built-in external feeds supplies a crafted feed configuration, the server fails to properly sanitize path components, allowing the attacker to traverse outside the intended directory and overwrite arbitrary files on the underlying filesystem. Exploitation requires low-level authenticated access (feed modification privileges) and no user interaction, and can be performed remotely over the network with low attack complexity and no special attack requirements (GitHub Advisory, Octopus Advisory).
A successful exploit allows an authenticated attacker to overwrite arbitrary files on the Octopus Server host, compromising the integrity and availability of the system. Depending on the server's configuration and the files overwritten (e.g., executable scripts, configuration files, or startup items), this can escalate to full remote code execution, resulting in high confidentiality, integrity, and availability impact on the vulnerable system. The vulnerability does not directly impact subsequent/downstream systems per the CVSS scoring, but RCE on an Octopus Server — which typically manages deployment pipelines and holds credentials for target environments — could enable significant lateral movement across an organization's infrastructure (GitHub Advisory, Octopus Advisory).
As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (GitHub Advisory). The CVE is not listed in the CISA Known Exploited Vulnerabilities catalog. The EPSS score is approximately 0.684% (51st percentile), indicating a relatively low but non-negligible probability of exploitation within 30 days. No threat actor attribution has been reported. The NVD SSVC assessment notes exploitation as "none" and the attack as non-automatable at this time.
../ sequences) in a feed parameter that is used to construct a server-side file path.cmd.exe, powershell.exe, /bin/bash, curl, wget) following feed configuration changes.Octopus Deploy has released patched versions addressing this vulnerability: 2026.1.11725, 2026.2.13344, and 2026.3.11816. Organizations should upgrade to one of these fixed versions as soon as possible. As an interim workaround, restrict feed modification permissions to only highly trusted users and audit which accounts currently hold permission to modify non built-in external feeds. Reviewing and tightening role-based access controls within Octopus Server can reduce the attack surface until patching is complete (Octopus Advisory, GitHub Advisory).
Coverage of CVE-2026-92355 has been limited to automated vulnerability tracking platforms and security news aggregators such as SecurityOnline.info, VulDB, and radar.offseq.com. No notable independent researcher commentary or significant social media discussion has been identified at this time (SecurityOnline).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."